- New Zealand
- Resources
- AML/CFT programme
How to Build a New Zealand AML/CFT Programme
A plain-English guide to establishing, implementing, maintaining and reviewing a New Zealand AML/CFT programme.
How this guide was researched and reviewedOn this page
Short answer
An AML/CFT programme is the written set of procedures, policies and controls used to detect, manage and reduce the ML/TF risks identified in the business’s risk assessment.
The programme must be based on the risk assessment, put into use and kept current. A document alone is not an implemented programme.
At a glance
The Programme Has Four Jobs
Follow the risk
Controls should respond to the risks identified in the written risk assessment.
Cover the duties
CDD, reporting, records, monitoring, people and other required areas should be addressed.
Guide daily work
Staff should be able to tell what to do, when to do it and where to record it.
Improve over time
Reviews, audit findings, incidents and business changes should feed back into the programme.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- AML/CFT programme
- The written procedures, policies and controls used to detect, manage and reduce the business’s ML/TF risks.
- Reporting entity
- A person or business that has duties under the AML/CFT Act for a covered activity.
- Procedure
- The steps a person follows to complete an AML/CFT task.
- Control
- A safeguard such as a check, approval, alert, limit or report.
- Risk-based
- Using stronger effort where risk is higher while still meeting every mandatory duty.
Part 1
What the Programme Should Cover
- Vetting and training for senior managers, the compliance officer and staff doing AML/CFT work.
- Standard, simplified and enhanced CDD, including delayed verification and reliance rules.
- Ongoing CDD, customer risk ratings and account or activity monitoring.
- Suspicious activity and prescribed transaction reporting.
- Keeping, protecting and disposing of AML/CFT records.
- Examining complex, unusually large or unusual patterns of activity.
- Controls for countries, products, delivery methods, anonymity and new technology.
- Internal communication, compliance monitoring, review and independent audit.
Part 2
Build It in the Right Order
- Step 1
Confirm the business is covered
Record the activities that make the business a reporting entity and any territorial or ordinary-course issue.
- Step 2
Complete the risk assessment
Assess customers, countries, products, services, transactions and delivery channels, using current national and sector information.
- Step 3
Turn risk into controls
For each important risk, set out who acts, what they do, when it happens, the evidence kept and the approval needed.
- Step 4
Build in every legal duty
Check the programme against sections 56 and 57 and current DIA guidance so that no required area is missed.
- Step 5
Implement and test
Train the right people, update systems and forms, test sample work and correct anything that does not work.
Part 3
What Good Evidence Looks Like
| Area | Evidence | Simple test |
|---|---|---|
| CDD | Files, verification, ownership and risk decisions | Can another trained person follow the decision? |
| Monitoring | Alerts, reviews and written findings | Are unusual patterns examined promptly? |
| Reporting | Escalations, decision notes and goAML receipts | Can the three-working-day deadline be proved? |
| People | Vetting, training and competency records | Do staff know what their role requires? |
| Review | Versions, change records and audit actions | Does the programme change when risk changes? |
Part 4
Maintain and Review the Programme
The risk assessment and programme should be reviewed regularly and when the business or its risks change. New products, technology, countries, customer types, delivery methods, findings and legal changes are common triggers.
A review should ask whether the written control remains adequate and effective, whether staff use it and whether it produces the expected result.
The programme and risk assessment are generally subject to an independent audit every three years, unless DIA gives a four-year timeframe or requests another time. High-value dealers have a different audit rule.
Part 5
Common Mistakes
- The programme repeats the Act but does not explain the business’s process.
- Controls do not match the risks in the risk assessment.
- CDD responsibilities are split across teams without a clear handover.
- Exceptions are allowed but no approval or record is required.
- Staff are trained on policy wording but not on realistic cases.
- An audit finding is closed by changing a document only.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Must the programme be in writing?
Yes. It must be written, based on the risk assessment and include adequate and effective procedures, policies and controls.
Who administers and maintains the programme?
The reporting entity must appoint a compliance officer to administer and maintain it. Senior managers and the wider business still have responsibilities.
Can a small business use a short programme?
It can be proportionate and easy to use, but it must still cover every duty that applies and respond to the business’s actual risks.
Can work be outsourced?
Some tasks may be outsourced, but the reporting entity keeps responsibility. Access, instructions, privacy, quality checks and evidence should be addressed.
When should the programme be updated?
Update it when risk, operations, law or findings show that a control is no longer adequate or effective. Do not wait for the next scheduled review.
Reference
Official Sources
This guide cites the following sources.
- Primary lawNew Zealand LegislationAnti-Money Laundering and Countering Financing of Terrorism Act 2009
The current New Zealand AML/CFT Act, including CDD, programme, reporting, audit and record duties.
- Regulator guidanceDepartment of Internal AffairsAML/CFT Programme Guidance 2026
Current guidance on establishing, implementing, maintaining and reviewing an AML/CFT programme.
- Regulator guidanceDepartment of Internal AffairsAML/CFT information and guidance
DIA’s current AML/CFT homepage, including guidance for reporting entities and its consolidated supervision role from 1 July 2026.
- Regulator guidanceDepartment of Internal AffairsAudit Guidance for Risk Assessment and AML/CFT Programme
Current guidance on audit timing, independence, scope, evidence and reporting.